CTI STIX SC Status Report www.oasis-open.org October 22, 2015.

Slides:



Advertisements
Similar presentations
Issue 134 Metamodel for OWL 2 Peter Haase, Elisa Kendall, Boris Motik, Evan Wallace.
Advertisements

A step-wise path to e61850 with UML IEC TC 57 WG10
Semantics Session 1 (mon 19, 16:30-18:00, Vulcania 1) Vocabularies: –Overview of vocabulary document (APM) –Discussion to resolve WD open issues (NG, AG,...)
ESSnet Stanprep The CEN Standardisation Process. CEN Overview: A standard (French: Norme, German: Norm) is a technical publication that is used as a rule,
Threat Modeling and Sharing. Summary Proposal to kick off Threat Modeling project – Multi-phase approach – Initially: create Cyber Domain PIM and STIX.
ITHAKA Preservation Metadata 2.0: Revising the Event Model A last-minute presentation on work currently in progress Evan Owens VP, Content Management ITHAKA.
Kick-off meeting Tuesday, June 02, 2015 Anders Östman Imad Abugessaisa.
1 CSL Workshop, October 13-14, 2005 ESDI Workshop on Conceptual Schema Language and Tools - Aim, Scope, and Issues to be Addressed Anders Friis-Christensen,
Inside View of DDI Version 3.0: Structural Reform Group Report Presented to IASSIST 25 May 2005 Edinburgh Scotland UK.
Ontology Engineering for the Comparison of Cadastral Processes Laboratory for Semantic Information Technology Bamberg University Claudia Hess, Christoph.
1 ISO – Metadata Next Generation International consensus being built on structured metadata within a broader Geomatics Standard under ISO Technical.
Agenda Model migration vs MDS upgrade Model migration overview Model migration – how does it work? Model package Demo.
Framework for Model Creation and Generation of Representations DDI Lifecycle Moving Forward.
MTEI Methods & Tools for Enterprise Integration
® Eurostep.ESUKPC v0.1©Copyright Eurostep Limited An Introduction to ISO STEP Part 25 David Price.
Method of Converting Resource definitions into XSD Group Name: WG3 (PRO) Source: Shingo Fujimoto, FUJITSU, Meeting Date:
From a Single Ontologically Sound Conceptual Model to Multiple Physical Schema Languages Bruce T. Bauman, U.S. DoD 1.
Provo, 16 Aug 2007 LMF meeting 1 Lexical Markup Framework: ISO Provo meeting Gil Francopoulo.
CTI STIX SC Kickoff Meeting July 16, 2015.
Faculty of Informatics and Information Technologies Slovak University of Technology Peter Kajsa and Ľubomír Majtás Design.
 Copyright 2005 Digital Enterprise Research Institute. All rights reserved. Towards Translating between XML and WSML based on mappings between.
Experiences with the Design and Development Process of DDI Requirements for Future Work Ideas for Improvement Joachim Wackerow.
Profiling Metadata Specifications David Massart, EUN Budapest, Hungary – Nov. 2, 2009.
Copyright © 2004 by The Web Services Interoperability Organization (WS-I). All Rights Reserved 1 Interoperability: Ensuring the Success of Web Services.
IVOA Registry videocon 2004/05/13-14 Gerard Lemson1 Model based schema.
ISO/IEC CD and WD : Core Model and Model Mapping ISO/IEC JTC1/SC32/WG September 2005, Toronto SC32/WG2 Japan (Kanrikogaku Ltd) Masaharu.
CTI STIX SC Monthly Meeting August 19, 2015.
Why Proposed TC Procedures? Define how TC reaches “completion” of what OASIS calls “Committee Specifications” TC procedures lead up to the OASIS process:
Ernest Micklei, PhilemonWorks.com UMLX: a pragmatic solution to documenting design Ernest Micklei
ModelPedia Model Driven Engineering Graphical User Interfaces for Web 2.0 Sites Centro de Informática – CIn/UFPe ORCAS Group Eclipse GMF Fábio M. Pereira.
Common Terminology Services 2 CTS 2 Submission Team Status Update HL7 Vocabulary Working Group May 17, 2011.
What is new in XPDL Robert Shapiro VP Global 360 XPDL 2.2 and 3.0 Editor BPMN 2.0 FTF Member Denis Gagné, CEO & CTO Trisotech XPDL 2.2 and 3.0 Co-Editor.
Dictionary based interchanges for iSURF -An Interoperability Service Utility for Collaborative Supply Chain Planning across Multiple Domains David Webber.
Representing Netconf Data Models using Document Schema Definition Languages (DSDL) Rohan Mahy Sharon Chisholm Lada Lhotka IETF 72 - Dublin.
All Presentation Material Copyright Eurostep Group AB ® A Meta-model of EXPRESS in UML for MOF and UML to EXPRESS David Price April 2002.
11 th NASA/ESA Workshop on Product Data Exchange 2009 Allison Barnard Feeney, NIST David Price, Eurostep.
CTI STIX SC Monthly Meeting October 21, 2015.
CTI CybOX SC Meeting November 19, 2015.
CTI CybOX SC Meeting October 29, 2015.
CTI CybOX SC Meeting August 27, 2015.
CTI STIX SC Monthly Meeting December 23, 2015.
WonderWeb. Ontology Infrastructure for the Semantic Web. IST Project Review Meeting, 11 th March, WP2: Tools Raphael Volz Universität.
OWL Web Ontology Language Summary IHan HSIAO (Sharon)
WG2A meeting 7-8 October 2004 Working Group 2A ECOSTAT Agenda item 9b Discussion on final Intercalibation register.
YANG Background and Discussion: Why we need a new language for NETCONF configuration modeling The YANG Gang IETF 70 Vancouver, Canada.
CTI STIX SC Status Report December 10, 2015.
ESA UNCLASSIFIED – For Official Use INSPIRE Orthoimagery TWG Status Report Antonio Romeo ESRIN 15/02/2012.
05 October 2010 HMA-FO Task 2: Feasibility Analysis Service HMA Follow On Activities Task 2: Feasibility Analysis Service (Sensor Planning Service) Monthly.
Contents Major issue states and transitions Tools.
OMG Architecture Ecosystem SIG Enterprise Data World 2011.
Modelling Australian geodetic data and metadata Roger Fraser & Nick Brown eGeodesy Working Group, Permanent Committee on Geodesy.
SHARING CYBER THREAT INTELLIGENCE JUST GOT A LOT EASIER
CTI STIX SC Monthly Meeting
STIX Interoperability
Data Models: IDEF1X Advantages: Core available from the MIP.
IAA Brand Review Recommendation to the Executive Committee
Introduction DoDAF 2.0 Meta Model (DM2) TBS dd mon 2009 VERSION 15
Introduction DoDAF 2.0 Meta Model (DM2) TBS dd mon 2009 VERSION 15
OASIS Overview TC Process
CTI TC Monthly Meeting Updates Session #1: 11:00 AM EST
Briefing on STIX | TAXII
OASIS OSLC Core TC Inaugural Meeting 12 November 2013
OASIS Overview TC Process
CTI Specification Organization
CTI TC Inaugural Meeting 18 June 2015
ETSI TC MTS TDL SC meeting Reports
ETSI TC MTS TDL SC meeting Reports
CTI STIX SC Monthly Meeting
ETSI TC MTS TDL SC meeting Reports
QoS Metadata Status 106th OGC Technical Committee Orléans, France
Presentation transcript:

CTI STIX SC Status Report October 22, 2015

The State of the Subcommittee is Good n 61 members / 6 observers n 3 active workproducts l STIX v1.2.1 language specifications l XML binding specification for STIX v1.2.1 l STIX v2.0 language specifications n Many active discussions on specific issues around the language n Many active strategic discussions l Serialization decisions (e.g., MTI) l Formal modeling approaches

STIX specification status and next steps n Multipart specification for the STIX language n STIX SC approved drafts n Draft specification package uploaded to CTI TC site – 10/15/15 n Awaiting TC motion and vote to move to Committee Specification for Pubic Review Draft n STIX Version Part 1: Overview. n STIX Version Part 2: Common. n STIX Version Part 3: Core. n STIX Version Part 4: Indicator. n STIX Version Part 5: TTP. n STIX Version Part 6: Incident. n STIX Version Part 7: Threat Actor. n STIX Version Part 8: Campaign. n STIX Version Part 9: Course of Action. n STIX Version Part 10: Exploit Target. n STIX Version Part 11: Report. n STIX Version Part 12: Extensions. n STIX Version Part 13: Data Marking. n STIX Version Part 14: Vocabularies. n STIX Version Part 15: UML Model. n Uml Model Serialization n XMI files n Diagrams

XML binding specification for STIX v1.2.1 n Consists of : l Textual specification document characterizing mapping rules to generate an XML Schema serialization from the STIX v1.2.1 language UML model l XML Schema reference implementation for STIX v1.2.1 n Status l Drafts are currently in authoring/editing process l Targeted for STIX SC review in November

STIX v2.0 specification status n Official kickoff was yesterday (10/21/15) n Currently selecting editors n Initiating deliberative process l Identifying and fleshing out use cases l Triage of issue trackers n Looking into options for issue “voting” l Plan to flesh out use cases iteratively while tackling issues l Plan to immediately begin discussing 2-3 high priority issues identified from list discussions

Active Discussion: Serialization Decisions n To date, only specified serialization has been XSD n What implementation serialization(s) is most appropriate? n Should we support multiple serializations? Which ones? n Strong consensus on the idea of specifying a Mandatory to Implement (MTI) serialization n Not yet enough information (still defining selection criteria and unknowns with how STIX will change in 2.0) to decide on MTI l Looks like current preference is leaning strongly to JSON

Active Discussion: Formal Modeling Approaches n Current STIX approach: formal UML structural model with textual explanation of semantics and manual serialization binding(s) n Proposed STIX approach: formal UML conceptual model (including explicit semantics) with auto-derived formal semantic serialization model (RDF/OWL) with subsequently auto-derived (tuned) implementation serialization(s) (JSON-LD, RDF/XML, etc)

Active Discussion: Formal Modeling Approaches n Potential advantages l Model specifies language semantics explicitly l Supports richer analysis approaches l Assurance of serialization mapping accuracy (full traceability and lossless translation) l Ease of integration with other relevant cyber ontologies n Potential questions/concerns l CTI TC community mostly unfamiliar with approach l Ease of use for implementers wanting simple serialization l Capabilities of default serializations like JSON-LD l Feasibility of available tooling